<div dir="ltr"><br clear="all"><div>Hey guys,<div><br></div><div>Our customer using adfs renewed their cert. After updating the their idp metadata, we received the following error messages:</div><div><br></div><div>shibd.log:2023-01-27 18:29:50 WARN XMLTooling.Decrypter [5] [default]: XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt - Error removing OAEPadding<br>shibd.log:2023-01-27 18:29:50 WARN OpenSAML.SecurityPolicyRule.XMLSigning [5] [default]: unable to verify message signature with supplied trust engine<br>shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]: detected a problem with assertion: Message was signed, but signature could not be verified.<br>shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]: error processing incoming assertion: Message was signed, but signature could not be verified.<br></div><div><br></div><div>We used the "explicit key" as the trust engine, our shibboleth SP is version 3.2.3-3.1.</div><div><br></div><div>We noticed that our customer's public cert has a size of 2237, all our other adfs customer's cert size is less than 2k, we suspected that might be an issue. </div><div><br></div><div><br></div><div>Any help is much appreciated.<br></div><div><br></div><div>Thanks</div><font color="#888888"><div>Terry</div></font></div></div>